By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials
Computing

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials

News Room
Last updated: 2025/04/22 at 9:01 AM
News Room Published 22 April 2025
Share
SHARE

In what has been described as an “extremely sophisticated phishing attack,” threat actors have leveraged an uncommon approach that allowed bogus emails to be sent via Google’s infrastructure and redirect message recipients to fraudulent sites that harvest their credentials.

“The first thing to note is that this is a valid, signed email – it really was sent from [email protected],” Nick Johnson, the lead developer of the Ethereum Name Service (ENS), said in a series of posts on X.

“It passes the DKIM signature check, and Gmail displays it without any warnings – it even puts it in the same conversation as other, legitimate security alerts.”

The email message informs prospective targets of a subpoena from a law enforcement authority asking for unspecified content present in their Google Account and urges them to click on a sites.google[.]com URL in order to “examine the case materials or take measures to submit a protest.”

Cybersecurity

The Google Sites URL displays a lookalike page that impersonates the legitimate Google Support page, and includes buttons to “upload additional documents” or “view case.” Clicking on either of the options takes the victim to a replica Google Account sign-in page, the only difference being that it’s hosted on Google Sites.

“sites.google.com is a legacy product from before Google got serious about security; it allows users to host content on a google.com subdomain, and crucially it supports arbitrary scripts and embeds,” Johnson said.

“Obviously this makes building a credential harvesting site trivial; they simply have to be prepared to upload new versions as old ones get taken down by Google’s abuse team. It helps the attackers that there’s no way to report abuse from the Sites interface, too.”

A clever aspect of the attack is the fact that the email message has the “Signed by” header set to “accounts.google[.]com” despite it having a “Mailed by” header with a completely unrelated domain (“fwd-04-1.fwd.privateemail[.]com”).

Phishers Exploit Google Sites and DKIM Replay

The malicious activity has been characterized as a DKIM replay attack, where the attacker first creates a Google Account for a newly created domain (“me@<domain>”) and then a Google OAuth application with the name that includes the entire content of the phishing message.

“Now they grant their OAuth app access to their ‘me@…’ Google account,” Johnson said. “This generates a ‘Security Alert’ message from Google, sent to their ‘me@…’ email address. Since Google generated the email, it’s signed with a valid DKIM key and passes all the checks.”

The attacker then proceeds to forward the same message from an Outlook account, keeping the DKIM signature intact, and causing the message to bypass email security filters, according to EasyDMARC. The message is subsequently relayed through a custom Simple Mail Transfer Protocol (SMTP) service called Jellyfish and received by Namecheap’s PrivateEmail infrastructure that facilitates mail forwarding to the targeted Gmail account.

“At this point, the email reaches the victim’s inbox looking like a valid message from Google, and all authentication checks show as passing SPF, DKIM, and DMARC,” EasyDMARC CEO Gerasim Hovhannisyan said.

“Because they named their Google account ‘me@’, GMail shows the message was sent to ‘me’ at the top, which is the shorthand it uses when a message is addressed to your email address – avoiding another indication that might send up red flags,” Johnson pointed out.

When reached for comment, Google told The Hacker News that it has rolled out fixes to stop the abuse pathway and emphasized that the company neither asks for account credentials, such as passwords or one-time passwords, nor directly calls users.

Cybersecurity

“We’re aware of this class of targeted attack from this threat actor, and have rolled out protections to shut down this avenue for abuse,” a Google spokesperson said. “In the meantime, we encourage users to adopt two-factor authentication and passkeys, which provide strong protection against these kinds of phishing campaigns.”

The disclosure comes nearly nine months after Guardio Labs revealed a now-patched misconfiguration in email security vendor Proofpoint’s defenses that threat actors exploited to send millions of messages spoofing various popular companies like Best Buy, IBM, Nike, and Walt Disney, and bypass authentication measures.

It also coincides with a surge in phishing campaigns that attachments in Scalable Vector Graphics (SVG) format to trigger the execution of HTML code that, in turn, redirects users to a rogue Microsoft login form or a fake web page masquerading as Google Voice to entice them into entering their credentials.

Russian cybersecurity company Kaspersky said it has observed over 4,100 phishing emails with SVG attachments since the start of 2025.

“Phishers are relentlessly exploring new techniques to circumvent detection,” Kaspersky said. “They vary their tactics, sometimes employing user redirection and text obfuscation, and other times, experimenting with different attachment formats. The SVG format provides the capability to embed HTML and JavaScript code within images, which is misused by attackers.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Fintech Isn’t Just Back, It’s Being Rearchitected For AI
Next Article Best iPhone Camera Accessories for Pro Photos and Videos
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The government invests 37 million in two Spanish technology: Sparc and Quantix
Mobile
XWayland 24.1.8 & X.Org Server 21.1.18 Further Address Yesterday’s Security Disclosures
Computing
Remarkable new AI can tell your age by looking at your eyes
News
This Australian moth uses the stars as a compass to travel hundreds of miles
News

You Might also Like

Computing

XWayland 24.1.8 & X.Org Server 21.1.18 Further Address Yesterday’s Security Disclosures

1 Min Read
Computing

Alibaba yields “good results” from three-year inspection, says regulator · TechNode

1 Min Read
Computing

Uber Eats now lets South Africans order from their seats at events

4 Min Read
Computing

What Is Google Ads Performance Max & How Does It Work? | WordStream

13 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?